The Group has established an "Information Security Committee" to hold regular meetings on the coordination and discussion of infocomm security and policy plans, resource scheduling, and other issues related to infocomm security management. The Group's CEO serves as the convener and holds information security committee meetings every six months. The contents are as follows:
(1) Submit a description of major capital security incidents and improvements.
(2) Propose the introduction of important information security systems or protective mechanisms to reduce operational risks and enhance information security capabilities.
(3) Review and propose amendments to the Group's important information security policies, implementation of information security plans, adjustments to the information security organization, and related resource allocation.
(4) Report on the implementation and evaluation of the information security management of each unit.
The Information Service Department of the Headquarters is the information security management unit responsible for the comprehensive management of the Group’s information security management work. In addition, a domestic professional information security company is appointed to serve as the information security technical consulting team to assist in the formulation (revision) of information security-related specifications, evaluation and suggestions regarding important information security mechanisms, monitoring and providing warnings regarding abnormal network connections, information security recommendations and professional training, information security testing and drills, handling and responses to major information security incidents, and audits of the information security management of the Group, in order to ensure that all units implement various information security management measures.
Infocomm Policy and Management
In addition to the necessary network/host defense architecture (such as VPNs, firewalls, intrusion detection, and antivirus software), each of the Group’s businesses has introduced a comprehensive information security mechanism to establish the Group's information security infrastructure, including:
Management Resource Input
(1) The Information Service Department of the headquarters is responsible for formulating the Group's information security management policies and related regulations, establishing an OA information environment and services based on high information security standards, deploying a group-wide monitoring mechanism, establishing strict management procedures for identity authentication, access authorization, data backup and information security auditing, and coordinating and managing the Group's various information security planning and implementation.
(2) Each operation team of the Group specifies the appointment of a resource security officer to implement the Group's requirements for the deployment of an operational environment, resource security mechanism, and related management work.
(3) In addition to assisting in deploying various security mechanisms, the Information Security Technical Support Team also provides 24/7 automated threat monitoring, event analysis, and alert processing services.
Information Security Certification